The GhostAction campaign has escalated sharply. As of October 9, security firm Socket said it had identified more than 500 GitHub accounts that committed a malicious workflow to tens of thousands of repositories since October 7 — including several organization-owned repositories reached through compromised contributors. The Hacker News reported the same figures, with additional coverage from Cyber Security News.
The finding extends what TrustGrade Crypto News covered October 8, when the campaign's return was first documented across roughly 772 repositories. The current scale is an order of magnitude larger.
The October 8 Burst
Socket's analysis centers on an October 8 burst in which two compromised maintainer accounts — henrywoo and kitao — pushed single-file commits adding .github/workflows/security-audit.yml to every repository they could write to. Despite the filename, the workflow performs no security review function. It collects credentials and POSTs them in cleartext to hxxp://193.32.204[.]199.
Socket observed the file in 346 repositories in that burst: 318 under the henrywoo namespace, 27 under kitao, and uber/athenadriver — an Uber-owned repository the henrywoo account can write to as its original author. That detail is the campaign's expensive pattern: the blast radius of a compromised maintainer is not their own projects but every repository, in every organization, their credential can touch.
The highest-exposure target was kitao/pyxel, an 18,420-star game-engine repository distributing through both PyPI and crates.io. The workflow's rendered payload named exactly the publishing credentials for both registries plus a GitHub personal access token, and the workflow ran successfully. As of October 9, Socket had observed no malicious package versions published to either registry from this activity.
What's New: Full-History Cloud Credential Sweeps
Earlier GhostAction waves — first documented by GitGuardian in September 2025 and again on its 2026 return — stole only GitHub Actions secrets stored in repository settings. This variant keeps that capability and adds a second collection method: a regex sweep of the working tree and the complete git history for 13 credential patterns, made possible by fetch-depth: 0, which checks out every branch and tag rather than a single shallow branch.
The pattern list reads as a shopping list of cloud and AI infrastructure: AWS long-term and temporary access key IDs, secret access keys and session tokens; Anthropic, OpenAI and OpenRouter API keys; GitHub classic and fine-grained personal access tokens; GitLab tokens; Google/Firebase API keys; Slack tokens; and SendGrid keys.
The most deliberate addition targets AWS. An AKIA key ID authenticates nothing on its own — the paired 40-character secret does, and it typically sits one or two lines away in a .env file or Terraform block. The payload captures a two-line window around every AWS key ID in both the working tree and the full history, reconstructing complete, usable key pairs. Because the history sweep reads rewritten and stale branches, it reaches credentials developers most likely believe were deleted long ago.
Defensive Implications
The two collection methods require different responses, and neither covers the other. Rotating GitHub Actions secrets does nothing for a credential committed into history; purging the working tree does nothing for Actions secrets. Maintainers of repositories that received an unexpected workflow commit should treat any successful run of that workflow as a full credential exposure event: rotate Actions secrets, rotate any cloud and AI keys ever committed, and audit git history — in the human-reviewed sense of the word — for the 13 pattern classes.
Socket noted it had identified no malicious packages published to PyPI or crates.io from this latest activity as of October 9. That restraint may not last: the campaign's earlier waves demonstrated that stolen publishing credentials are the bridge from repository compromise to downstream supply-chain infection.
TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.